The Home Depot breach of 2014 exposed 56 million payment cards and 53 million customer email addresses - larger than Target's 2013 breach in card scope and occurring during the extended period in which the industry was still digesting Target's implications. The attackers used a vendor's stolen credentials to enter Home Depot's network, deployed a custom variant of BlackPOS memory-scraping malware on point-of-sale terminals across approximately 2,200 US and Canadian Home Depot stores, and operated the malware undetected from April to September 2014 - five months during which every card swipe at those terminals was captured.

Home Depot's response to the breach became a benchmark for what improved retail breach handling looked like after Target. The company disclosed the breach relatively promptly (within weeks of discovery), offered free identity protection to affected customers without requiring them to prove harm, established a dedicated call center, and cooperated with law enforcement. Its CEO testified before Congress. The breach settlement - $179.5 million to financial institutions and a $25 million consumer settlement - was substantial. But unlike Target, Home Depot's leadership retained their positions and the company emerged with a reputational recovery that Target did not fully achieve for several years.

The Attack: Vendor Credentials to Global POS Deployment

The Home Depot breach entry vector was a third-party vendor - a supplier whose credentials had been stolen via malware that infected a vendor employee's personal computer. The vendor had some level of access to Home Depot's network, and the attackers used those credentials to gain an initial foothold. From that foothold, they moved to Home Depot's corporate network and identified the payment processing environment.

The key escalation was an exploitation of a zero-day vulnerability in Windows XP. Home Depot's POS terminals ran on Windows XP, which had reached end-of-life in April 2014 (the same month the Home Depot breach began). Microsoft had stopped providing security patches for Windows XP. The attackers used a privilege escalation vulnerability in XP to gain the level of access needed to deploy malware to the POS systems at scale.

The malware deployed was a custom variant of BlackPOS (also known as "FrameworkPOS" in some analyses) - the same malware family used in the Target breach, though with modifications that allowed it to evade the specific security tools Home Depot had in place. The malware collected card track data from the POS terminal's memory as cards were swiped, wrote the data to local files, and periodically transmitted it to attacker-controlled external servers.

[TECHNICAL NOTE]
The Home Depot breach highlighted the systemic risk of running payment card infrastructure on end-of-life operating systems. Windows XP's extended support ended April 8, 2014 - the same month Home Depot's breach began. Major retailers' POS terminal environments were deeply tied to Windows XP because POS software had been written and certified for XP, and recertification for newer operating systems required significant vendor cooperation, testing, and PCI DSS recertification. The economics and operational complexity created inertia that kept major retailers on an OS with no security patches. The attackers exploited this inertia directly - using a Windows XP privilege escalation vulnerability that had not been patched (and would not be patched) to install malware on the POS systems. The PCI DSS standard had included requirements for operating system support status in its assessments, but enforcement was inconsistent. After Target and Home Depot, the card brands increased pressure on retailers to migrate away from XP, and Microsoft extended security updates (for a fee) to some large enterprises and government customers. The broader lesson - that running payment infrastructure on unsupported operating systems creates an unpatched attack surface that motivated adversaries will find and exploit - seems obvious in retrospect. The operational reality was that POS terminal replacement at 2,200 stores was a multi-year, billion-dollar program.

Scale and Card Data Sales

The 56 million cards stolen from Home Depot appeared for sale on criminal card marketplaces in September 2014 - the same week Home Depot confirmed the breach. The marketplace "Rescator," operated by the same Ukrainian criminal network that had sold the Target cards, began selling what it called "European Sanctions" - batches of cards identified as coming from Home Depot based on issuer and card number patterns. The names matched in format to the Rescator batches that appeared after Target.

This rapid appearance of the stolen cards on underground markets demonstrated that the criminal operation had a complete pipeline from breach to monetization that could operate in near-real-time. The card data was formatted, sorted by card type and issuing bank (more valuable), priced, and available for purchase within days of the attacker's choosing to activate the sale. The Home Depot cards sold for between $9 and $45 per card depending on type and freshness.

[WARNING]
The Home Depot breach underscored how the transition to EMV chip-and-PIN cards - which both Target and Home Depot breaches accelerated in the US - changes but does not eliminate card fraud risk. EMV chip cards create a unique cryptogram for each transaction, making the card data useless for card-present fraud at chip-enabled terminals. Stolen magnetic stripe data from Home Depot, once US terminals transitioned to chip readers, would be usable only at merchants still accepting magnetic stripe swipes (many merchants outside the US) or for card-not-present (online) fraud. The liability shift for EMV in the US occurred October 2015 - one year after the Home Depot breach. After the shift, liability for card-present fraud at non-EMV-enabled terminals shifted from card issuers to merchants. This created financial incentives for merchants to upgrade to chip-capable terminals faster than previous PCI DSS compliance timelines had required. The shift did not address card-not-present fraud, which increased substantially after the liability shift as fraudsters moved from the now-protected in-store channel to online purchases. The Home Depot breach data remained valuable for online fraud for years after the EMV transition.

Settlements and Legislative Response

Home Depot's total breach-related costs exceeded $298 million before insurance recovery. The company recovered approximately $100 million from insurance, leaving net breach costs of approximately $200 million. Specific components included a $179.5 million class settlement with financial institutions (card issuers seeking recovery for fraud costs and card replacement), a $25 million consumer settlement, and additional regulatory costs.

Home Depot became one of the lead cases cited in Congressional hearings on data breach notification legislation. The hearings brought together retail industry representatives, financial institution representatives, and consumer advocates in a forum that highlighted the fundamental economic tension in the breach ecosystem: retailers bear the costs of securing payment data but much of the downstream fraud cost falls on card-issuing banks. This misalignment of costs had been cited as a structural reason why retail security investment was insufficient, but the breach notification bill being considered did not address this structural issue. The bill did not pass during that Congress; federal breach notification legislation has not been enacted as of 2025.

[IOC]
Home Depot breach summary: initial access via third-party vendor credentials stolen from vendor employee's personal computer. Privilege escalation: unpatched Windows XP zero-day (XP had reached end-of-life April 8, 2014, the month the breach started). Malware: custom BlackPOS variant ("FrameworkPOS") deployed on POS terminals at approximately 2,200 US and Canadian Home Depot stores. Data captured: 56 million payment card track 1 and track 2 data; 53 million customer email addresses. Duration: April to September 2014 (approximately 5 months). Detection: combination of bank fraud pattern analysis and law enforcement notification, September 2014. Card data appeared on Rescator criminal marketplace ("European Sanctions" batch) within days of disclosure. Attribution: Ukrainian criminal network associated with the Target breach Rescator operator. Arrests: Ukrainian suspect Andrei Khilkov indicted (2018); Sergey Medvedev (Stells, administrator of criminal forum Infraud) sentenced 10 years (2021, unrelated but same criminal ecosystem). Settlements: $179.5M financial institution class settlement; $25M consumer settlement. Total company costs: approximately $298M pre-insurance. Insurance recovery: approximately $100M. Congressional testimony: Home Depot CEO Craig Menear testified before Senate Commerce Committee. EMV transition acceleration: Home Depot was among first major retailers to complete full EMV chip-and-PIN terminal rollout, completing transition in 2015.